Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/event-handler-receiver.js

4 lines
154 B
JavaScript

document.getElementById('my-id').onclick = function() {
this.parentNode.innerHTML = '<h2><a href="' + location.href + '">A link</a></h2>'; // NOT OK
};